airdrop[.]t3rn[.]lol
“BRN to TRN Claim”
airdrop.t3rn.lol — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: MetaMask; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 2/93 (Fortinet, Gridinsoft); 1 external blocklist match (ScamSniffer); PhishDestroy score 71/100.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
airdrop.t3rn.lol is flagged as a brand‑impersonation site that targets Metamask users. The domain was registered on 21 February 2026 and resolves to the Cloudflare‑owned address 172.67.137.122, which is advertised as being located in the United States under ASN 13335. The site is currently taken offline, but historical data show it was listed on two public phishing blocklists, PhishDestroy and ScamSniffer, confirming that security operators have observed malicious activity associated with the host. VirusTotal analysis recorded two positive detections out of ninety‑three scanners, indicating that at least a small subset of AV engines identified the domain as suspicious.
The TLS certificate presented on the site is labelled “WE1”, a weak indicator that the certificate may be self‑signed or otherwise low‑trust. Gridinsoft assigned a trust score of 10 / 100, reinforcing the low confidence in the domain’s legitimacy. The page title captured during the brief observation period reads “BRN to TRN Claim”, which aligns with the declared scam type of a crypto‑related scheme. The intelligence explicitly notes that the site impersonates Metamask, but no additional content—such as login forms, redirects, or malicious payloads—has been publicly disclosed.
Because the domain is already listed on multiple blocklists and exhibits low trust metrics, defensive teams should continue to deny any outbound connections to 172.67.137.122 and add a rule to block the fully qualified domain name airdrop.t3rn.lol at the DNS level. Monitoring of the hosting ASN for future domains that resolve to the same IP range is advisable, as Cloudflare often serves as a shared platform for both legitimate and malicious actors. Analysts should also watch for re‑registration of the domain or the appearance of similar sub‑domains that reuse the “airdrop” keyword, which is a common lure in crypto‑drain campaigns.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب